Back to Blog
Launch Strategy7 min readSeptember 7, 2026

EU Cyber Resilience Act Reporting Duties Start 11 September

From 11 September 2026, anyone placing connected software on the EU market must report actively exploited vulnerabilities within 24 hours. The obligation covers products already on sale, not just new ones.

Marcus Lee

Marcus Lee

Community at NeedBase

From 11 September 2026, if you place a product with digital elements on the EU market and you learn that one of its vulnerabilities is being actively exploited, you have 24 hours to file an early warning with the EU. This is not a future milestone anymore. It is the first mandatory reporting obligation under the Cyber Resilience Act (CRA), and it lands this week.

"Product with digital elements" is defined broadly enough to catch most software sold into the EU, whether or not you have any physical presence there. If you sell a SaaS product, a plugin, a connected device's firmware, or anything with software that can connect to a network or another device, read the next section carefully.

What actually triggers a report

Not every CVE. The obligation is narrower than the CRA's reputation suggests: it applies only when a vulnerability in your product is being actively exploited in the wild, or when you experience a severe incident affecting the security of the product. A vulnerability sitting unexploited in your codebase, however serious its CVSS score, does not by itself trigger the clock.

Once it does, the timeline is specific and short. An early warning within 24 hours of becoming aware. A full notification within 72 hours, with more detail on severity and cause. A final report due no later than 14 days after a corrective measure becomes available for an actively exploited vulnerability, or within a month for a severe incident. You report once, through the CRA's Single Reporting Platform, to your national Computer Security Incident Response Team, which then shares it with other relevant CSIRTs across the EU.

The part founders miss: it is not just new launches

The obligation is not limited to products you ship from here on. It also covers products already on the EU market before the CRA applied in full โ€” meaning a feature you shipped two years ago and have not touched since is still in scope if it is still being sold or supported today. "We built that before any of this existed" is not a defence under the reporting rule.

This is a genuinely different obligation from the security work most small teams already do. Patching a vulnerability is an engineering task. Reporting one that is actively being exploited, on a legal clock, to a specific regulator, through a specific platform, is a compliance task that someone on your team needs to own before the first incident forces the question.

What a small team should do this week

Identify what you sell into the EU. If any customer, free or paid, is in the EU and your product has digital elements, you are in scope. Nationality of your company is irrelevant; the market you sell into is what counts.

Name one person who owns this. Not a committee, one person who knows that "actively exploited" is the trigger, knows roughly what a report needs to contain, and knows where the Single Reporting Platform is. Finding this out during an actual incident costs you hours you do not have inside a 24-hour window.

Separate this from your existing vulnerability handling. Your dependency scanner, your bug bounty inbox and your on-call rotation are all upstream of this. What changes on 11 September is what happens after you confirm exploitation: a legal deadline now sits on top of the technical response.

Do not over-report. The instinct once you know this exists is to file on anything that looks bad. Reserve it for confirmed active exploitation or a genuine severe incident โ€” over-reporting wastes the one resource this rule is trying to conserve, which is a regulator's attention on things that actually matter.

What is still ahead

This is the first CRA deadline, not the last. Full compliance with the CRA's broader security-by-design and vulnerability-handling requirements is due by December 2027, and the reporting platform itself was still finishing security testing in the run-up to this week's launch. Expect friction in the early months as both companies and the platform adjust โ€” but expect the friction to be your problem to manage, not a reason the deadline moves.

The bottom line

If you sell software into the EU, a legal 24-hour reporting clock starts running the moment you confirm active exploitation, from this week onward, on products old and new alike. The work required before Thursday is small โ€” know that you are in scope, name an owner, know where to report โ€” but skipping it means learning the process for the first time during an actual breach, which is the worst possible moment to learn it.

Found this useful?

Share it with a founder who needs it.

Ready to launch your product?

Join thousands of makers who launched on NeedBase.

Submit Your Product โ†’